Bitcoin Forum

Economy => Scam Accusations => Topic started by: DireWolfM14 on January 16, 2019, 06:54:30 PM



Title: Malware targeting Windows Clipboard
Post by: DireWolfM14 on January 16, 2019, 06:54:30 PM
There's a malware being spread by torrent movie files that targets bitcoin addresses copied to the Windows clipboard.  If you use torrent to download movies on Windows machines be very careful when copying and pasting bitcoin addresses.

More information here:
https://www.bleepingcomputer.com/news/security/clipboard-hijacker-malware-monitors-23-million-bitcoin-addresses/


Title: Re: Malware targeting Windows Clipboard
Post by: suchmoon on January 16, 2019, 07:00:38 PM
What I don't get is why it needs to "monitor 2.3 million address" like the article claims. You'd think it would just look for a string or regex match and replace it.


Title: Re: Malware targeting Windows Clipboard
Post by: DireWolfM14 on January 16, 2019, 07:35:34 PM
What I don't get is why it needs to "monitor 2.3 million address" like the article claims. You'd think it would just look for a string or regex match and replace it.

Good question.  Possibly to ensure they are bitcoin addresses, and not LTC or ather addresses with a similar string length.  A conscientious scammer?  I'd be interested to know where the list of addresses was obtained.


Title: Re: Malware targeting Windows Clipboard
Post by: Quintrix on January 16, 2019, 11:36:03 PM
This is one of the reasons why you should not in a hurry to transact and protect your computer with powerful antivirus, in my case I always remember the first three and last three digits of my Bitcoin addresses and avoid using to many addresses


Title: Re: Malware targeting Windows Clipboard
Post by: coinlocket$ on January 17, 2019, 11:31:35 AM
Yep, already eared about at this malware about 1 month ago somewhere. Is it not detected like a virus for normal antivirus?


Title: Re: Malware targeting Windows Clipboard
Post by: Harlot on January 17, 2019, 11:53:47 AM
There's a malware being spread by torrent movie files that targets bitcoin addresses copied to the Windows clipboard.  If you use torrent to download movies on Windows machines be very careful when copying and pasting bitcoin addresses.
Where did you get this information? There was no statement saying that the malware came from a downloaded movie from a torrent but from a software disguised as a Radio/TV watcher named "All-Radio 4.27 Portable". Nevertheless we should always avoid downloading things even on torrents as you are never safe from this malwares and spywares.
This infection was spotted as part of the All-Radio 4.27 Portable malware package that was distributed this week. When installed, a DLL named d3dx11_31.dll will be downloaded to the Windows Temp folder and an autorun called "DirectX 11" will be created to run the DLL when a user logs into the computer.


Title: Re: Malware targeting Windows Clipboard
Post by: DireWolfM14 on January 17, 2019, 01:49:38 PM
Where did you get this information?

This was the original story I read:

https://cryptodaily.co.uk/2019/01/malware-from-pirate-bay-replaces-btc-eth